CVE-2026-67961: O2OA O2OA vulnerability
Published Aug 17, 2026
·Updated
An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.
Affected Software
1 affected component
O2OA O2OA=10.0.2
Event History
Aug 17, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-67961?
CVE-2026-67961 has a risk score of 44, indicating a moderate level of severity.
2
How do I fix CVE-2026-67961?
To remediate CVE-2026-67961, it is recommended to update O2OA to the latest version that addresses the vulnerability.
3
Who is affected by CVE-2026-67961?
CVE-2026-67961 affects users of O2OA version 10.0.2 who utilize the sandbox mechanism for script execution.
4
What is the impact of CVE-2026-67961?
The impact of CVE-2026-67961 allows a local attacker to execute arbitrary code, potentially compromising the integrity of the system.
5
When was CVE-2026-67961 published?
CVE-2026-67961 was published on August 17, 2026.